Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

0% Positive

Analyzed from 206 words in the discussion.

Trending Topics

#put#hours#right#npm#account#start#deal#minimum#number#don

Discussion (12 Comments)Read Original on HackerNews

alpineman•about 1 hour ago
>> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.

'what time shall we put here?'

'what's the longest hangover you ever had?'

'let's put 72 hours'

Waterluvian•37 minutes ago
A weekend plus a day to deal with things seems like a decent minimum duration when it’s somewhat arbitrary what the right number is.
datakan•23 minutes ago
I don't think so at all. People go on vacation all the time. This should be 30 days not 3.
Waterluvian•17 minutes ago
That's the usual runaway problem, right? Why not 60 then? People go on sabbaticals! etc etc.

I feel like the only way to be wrong for this class of problem is to believe that there's a singular right answer. Just pick something reasonable (like how weekends are a fairly common thing, so don't make it shorter than 48 hours). Start there, then see how much of an issue persists. No matter what, at scale you'll find someone complaining that the number is too little, and people complaining that it's too much. Eventually you just have to tell the complainers to deal with it.

normie3000•8 minutes ago
It's often not the maintainer that removes a poisoned release, it's the npm security team/tools. So unless the whole team takes a month off, we're all safe.
hncsiocp9x•about 1 hour ago
Been quietly thinking this for years
pluto_modadic•about 1 hour ago
the bare minimum award, for the only language and only registry where this regularly happens.